Data Protection

Data Processing Addendum

Before drafting, establish **which regime governs** — it follows the controller’s establishment, not the processor’s. A DIFC controller sending data to a mainland processor is making a **restricted transfer**, because the mainland is not on the DIFC adequacy list. That single fact changes what this addendum has to contain.

Download as Word6 pages20 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Data Processing Addendum

Controller to processor — UAE, DIFC and ADGM

Before drafting, establish which regime governs — it follows the controller’s establishment, not the processor’s. A DIFC controller sending data to a mainland processor is making a restricted transfer, because the mainland is not on the DIFC adequacy list. That single fact changes what this addendum has to contain.

ItemDetail
Controller[NAME], [licence] [NUMBER]
Controller’s jurisdiction[Mainland / Free zone / DIFC / ADGM]
Processor[NAME], [licence] [NUMBER]
Processor’s jurisdiction[DETAIL]
Governing regime[Federal PDPL / DIFC DP Law 5/2020 / ADGM DP Regulations 2021]
Is this a restricted transfer?[Y/N] — see Section 2
Main agreement[TITLE] dated [DATE]
Categories of data[LIST]
Special or sensitive categories?[Y/N — identify]
Data subjects[Employees / customers / applicants / other]
DurationFor the term of the main agreement
Sub-processors approved[LIST / None]

1. Which Regime Applies

Controller established inGoverning lawRegulator
UAE mainlandFederal Decree-Law 45/2021 (PDPL)UAE Data Office
Free zone without its own data lawFederal PDPLUAE Data Office
DIFCDIFC Data Protection Law 5/2020, as amendedDIFC Commissioner
ADGMADGM Data Protection Regulations 2021ADGM Office of Data Protection

1.1Note the status point carried through this library: aspects of the federal regime depend on the PDPL Executive Regulations, whose publication status is reported inconsistently. Where the federal analysis is uncertain, apply contractual safeguards and document the approach rather than relying on an unconfirmed position.

2. Transfer Position

2.1Where the Controller is established in DIFC or ADGM and the Processor is elsewhere, the disclosure is a transfer out of that jurisdiction and requires a lawful basis.

Generated from www.helionerp.com1

5 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Establish the governing regime first

It follows the controller’s establishment. A DIFC controller is governed by DIFC Law 5/2020 and regulated by the DIFC Commissioner; a mainland or ordinary free zone controller by the federal PDPL. An addendum citing the wrong law names the wrong regulator, the wrong rights and the wrong timelines.

DIFC to mainland is a restricted transfer

The UAE mainland is not on the DIFC adequacy list. A DIFC controller engaging a mainland processor — a payroll bureau, an IT provider, a bank — is making a restricted transfer requiring safeguards. This happens constantly within groups and is almost never documented.

The three adequacy lists differ

DIFC, ADGM and the federal regime each take their own position. A destination acceptable under one is not automatically acceptable under another. Check the list for the exporting jurisdiction and record the date checked, because the lists change.

Twenty-four hours for breach notification

The controller carries the regulatory deadline, and a processor notifying "promptly" several days later has consumed most of it. Twenty-four hours is a demanding but achievable standard, and it is the single most valuable clause in the addendum.

Do not let the processor notify the regulator

A processor contacting a regulator or data subjects on its own initiative removes the controller’s ability to manage the assessment and the message. Clause 4.4 reserves that decision to the controller.

Require notification before the investigation is complete

Processors delay notification while establishing scope, which is exactly backwards. Initial notification should be immediate and incomplete, with detail following. Clause 4.3 says so explicitly.

Name the purpose specifically

A purpose stated as "provision of the services" instructs nothing and permits almost anything. Schedule 1 requires the actual purpose. This is the same discipline as the purpose clause in an NDA and it matters for the same reason.

Ask where the data actually sits and who can reach it

Cloud services distribute processing across regions, and support teams access data from wherever they are. Schedule 1 asks for locations and access, including remote support. Remote access is a transfer even where nothing is downloaded.

Control sub-processors properly

Require prior written authorisation, a list of those approved, equivalent obligations flowed down, and continuing liability. A general consent to any sub-processor the processor chooses gives the controller no visibility of where its data ends up.

Make the security measures specific

A clause requiring "appropriate technical and organisational measures" is unenforceable in practice because nobody can say what was promised. Schedule 2 lists fourteen measures with a yes or no against each, which is checkable at audit and at breach.

Decide whether liability sits inside the cap

A data breach can generate regulatory penalties and claims far exceeding the contract value. Whether that liability is subject to the main agreement’s cap is the most negotiated point here, and leaving it unstated favours the processor.

Deletion needs a carve-out for backups

Backup systems cannot be selectively purged, so a deletion clause with no exception is breached the moment it is signed. Permit retention where required by law or by bona fide backup policies, under continuing obligations.

Employee data is the volume case

Payroll, visa records, passport copies, medical testing and health insurance data all flow to processors, and much of it is sensitive. Any payroll or HR provider needs this addendum, and the sensitive category question in Schedule 1 is usually answered yes.

Audit rights need to be usable

Rights that can only be exercised with lengthy notice, at the controller’s expense, once every several years, are decorative. Reasonable notice, annually, plus a right after a breach, is a workable formulation — and a current independent certification often satisfies it in practice.

Current as of

Reflects UAE, DIFC and ADGM positions current as of {{DATE OF USE}}. **The status of the federal PDPL Executive Regulations is reported inconsistently and must be verified.** Adequacy lists, transfer mechanisms, breach notification deadlines and DIFC requirements including those for automated systems all change — confirm with the relevant regulator or a UAE data protection adviser.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.